← Password Managers
F

1Password

Fail
AgileBits · 🇺🇸 United States
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
App: com.onepassword.android
Manufacturer: AgileBits Inc.

⚠️ The bottom line

1Password records every time you unlock your vault, create an item, or complete onboarding. If you're on a business plan, your employer's IT admin decides whether this happens — you can't turn it off yourself. Moving to Electron means 1Password inherits every Chrome vulnerability. CVE-2024-42219 let malware on your Mac steal vault items through a process communication flaw. Your password manager has the same attack surface as a web browser.

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
Audited by: Cure53 (pen test, May 2023) · ISE (pen test, Sep 2022)
An audit is a snapshot, not a guarantee. How reliable are these auditors?
Spying
0/4 N/A
Is someone spying on me?
Data Sharing
0/4 N/A
Who gets my data?
Security
4/4 EXTREME
Is it actually secure?
Honesty
3/4 HIGH
Can I trust what they say?
REPLACE Extreme risk. Look for alternatives or lock down hard.
Privacy-respecting alternatives
KeePassXC
Zero cloud, zero telemetry, fully offline. Your vault never touches a server
No cloud sync — you manage the database file yourself
Moderate effort
See report →
Bitwarden
Open source, third-party audited, can self-host
Cloud-synced (their servers), but open source and audited
Easy switch
See report →
6Contradictions
3Critical
1High
2Medium
5Sources
Findings by concern
Security 4/4 EXTREME 4 findings
⚠️ criticalfirmware analysis vs app permissions
Moving to Electron means 1Password inherits every Chrome vulnerability. CVE-2024-42219 let malware on your Mac steal vault items through a process communication flaw. Your password manager has the same attack surface as a web browser.

What they claim: 1Password uses AES-256-GCM with 650,000 PBKDF2 iterations plus a 128-bit Secret Key

What we found: CVE-2024-42219 (critical): macOS inter-process communication bypass allowed local malware to exfiltrate vault items. CVE-2024-42218 (high): macOS outdated version bypass. CVE-2023-4863 (critical): inherited libwebp heap buffer overflow from Electron framework. The move to Electron introduced an entire browser attack surface into a password manager.

⚠️ criticalpolicy claims vs app permissions
If your company uses 1Password Business, your IT admin controls whether your usage is tracked. You're storing your most sensitive work credentials in a tool where someone else decides your privacy settings.

What they claim: 1Password privacy policy states telemetry is 'optional' and can be disabled

What we found: For personal/family accounts telemetry is opt-in. But for Teams and Business accounts (where the most sensitive corporate credentials are stored), telemetry is enabled by default and individual team members cannot opt out — only account owners can. The people with the least control over their data are in the most sensitive environments.

⚡ highfirmware analysis vs regulatory findings
An attacker who compromised Okta got into a 1Password employee's session. No user data was stolen, but the attacker was inside 1Password's internal systems. One compromised vendor away from a much worse outcome.

What they claim: 1Password has never suffered a data breach and maintains strong audit certifications

What we found: 1Password holds SOC 2 Type 2, ISO 27001:2022, and multiple ISO certifications. However, the October 2023 Okta incident exposed 1Password's internal systems to an attacker who accessed an IT team member's HAR file. While no user data was compromised, the incident demonstrated supply-chain risk through identity providers.

⚫ mediumpolicy claims vs firmware analysis
Even though 1Password can't see your passwords, they can see exactly when you access them, from which device, and how often. If this telemetry data is breached, an attacker knows your daily routine and which accounts matter most to you.

What they claim: 1Password states 'we can never see your passwords' and operates zero-knowledge architecture

What we found: Telemetry endpoint telemetry.1passwordservices.com collects event data including timestamps of every unlock, vault access, and item interaction. While vault contents aren't transmitted, the behavioral metadata reveals when users access passwords, how often, and from which devices — a detailed usage fingerprint.

Honesty 3/4 HIGH 2 findings
⚠️ criticalpolicy claims vs firmware analysis
1Password records every time you unlock your vault, create an item, or complete onboarding. If you're on a business plan, your employer's IT admin decides whether this happens — you can't turn it off yourself.

What they claim: 1Password markets itself as a privacy-first product — 'your data is your data'

What we found: 1Password added telemetry in 2023 that collects usage data including unlock events, item creation, onboarding completion, device type, and account metadata. For business accounts, telemetry is ON by default and individual employees cannot opt out — only account owners can disable it.

⚫ mediumfirmware analysis vs app permissions
When 1Password crashes, it sends a report to Microsoft's servers. Crash dumps can contain fragments of whatever was in memory — potentially including decrypted vault data that was being displayed.

What they claim: 1Password uses crash reporting via in.appcenter.ms (Microsoft App Center)

What we found: Crash reports can contain memory dumps with potentially sensitive data. The app also connects to multiple analytics endpoints. For a product whose entire value proposition is keeping secrets, any outbound data transmission is a potential attack surface.

Sources